[openpgp] Re: WG: BSI view on KEM combiners
Falko Strenzke <falko.strenzke@mtg.de> Tue, 10 September 2024 11:55 UTC
Return-Path: <falko.strenzke@mtg.de>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 844CCC14F6FC for <openpgp@ietfa.amsl.com>; Tue, 10 Sep 2024 04:55:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mtg.de
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pRBaPrFQjbUu for <openpgp@ietfa.amsl.com>; Tue, 10 Sep 2024 04:55:26 -0700 (PDT)
Received: from www.mtg.de (www.mtg.de [IPv6:2a02:b98:8:2::2]) (using TLSv1.3 with cipher TLS_CHACHA20_POLY1305_SHA256 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 88BBCC14F6EA for <openpgp@ietf.org>; Tue, 10 Sep 2024 04:55:25 -0700 (PDT)
Received: from minka.mtg.de (minka [IPv6:2a02:b98:8:1:0:0:0:9]) by www.mtg.de (8.18.1/8.18.1) with ESMTPS id 48ABtJSD008684 (version=TLSv1.3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256 verify=NOT); Tue, 10 Sep 2024 13:55:19 +0200
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mtg.de; s=mail201801; t=1725969319; bh=C7P0VwTJ/o6LI5MNf26Rv8EL9YRMaokkTH3TSpOh+r0=; h=Date:From:Subject:To:References:In-Reply-To; b=CTtVyiTOicvEmnOo7dHcREL+/2cj9xNckNUxa8xaec4ZjcFfeX76o9XLJz+t1hyV0 H85ziwW0bIfmmmDN9Tbuvlz+Aezq1Fch7sao+v46oLcy1etMwT2qavPjjj3AFjnUlE uk/RLivw1mrfor0ptNH8beRslSHHNTTw+PKNe8mUZVGF3dSoPHxbaqjsJFjOFdeysx NBgGdKaLjN3ZDZFu7uzEIRYFkZL7hxCtgoDgOg/qUjDQ9RFWdL/RZsIIc0ML44jtHu jVDGdNAPT/zqKqzGqvgxEoXIUh5MdvKK3MZOePPpxC62WIJkNbCFLKsYQtzHaWhxTV ZdiwxZV5ng6Hw==
Received: from [10.8.0.100] (vpn-10-8-0-100 [10.8.0.100]) by minka.mtg.de (8.18.1/8.18.1) with ESMTPS id 48ABtIEk030845 (version=TLSv1.3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256 verify=NOT); Tue, 10 Sep 2024 13:55:18 +0200
Message-ID: <528f96b5-b342-407a-b5f7-2e8afc16f1b8@mtg.de>
Date: Tue, 10 Sep 2024 13:55:18 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
From: Falko Strenzke <falko.strenzke@mtg.de>
To: "D. J. Bernstein" <djb@cr.yp.to>, openpgp@ietf.org, Paul Wouters <paul@nohats.ca>
References: <20240909145649.389542.qmail@cr.yp.to>
Content-Language: en-GB
Organization: MTG AG
In-Reply-To: <20240909145649.389542.qmail@cr.yp.to>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms080409080902010706090708"
Message-ID-Hash: ZQODNO562ZMK7RZHEP44N4YFJ4HQ56VB
X-Message-ID-Hash: ZQODNO562ZMK7RZHEP44N4YFJ4HQ56VB
X-MailFrom: falko.strenzke@mtg.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: WG: BSI view on KEM combiners
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/6Kf5d4Bgyz3ogZwb4RVcwdyGFoM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
@ Dan Thanks for summarizing the history of events in CFRG regarding the KEM combiner question, that saved me the effort of doing something similar myself. Further comments inline... Am 09.09.24 um 16:56 schrieb D. J. Bernstein: > Paul Wouters writes: > [ regarding draft-connolly-cfrg-xwing-kem: ] >>>> That draft will be adopted in CFRG. >>> Evidence? >> It seems to me, there is consensus for that document > Evidence? Links? > > Here's contrary evidence. First, the CFRG discussion of KEM combiners > has had quite a few different proposals that haven't been withdrawn: > e.g., the generic Ounsworth proposal, the much more specific X-Wing > proposal that you're advocating (care to explain why?), and the > intermediate Chempat proposal. Our proposed construction in draft-ietf-openpgp-pqc is indeed based on the generic construction that was the first input to CFRG in this discussion (as I recall it) (see for instance https://mailarchive.ietf.org/arch/msg/cfrg/OSG9rayj_-FAmIIXa8BuJ39HvWo/) The security of the construction was never in question. The only recent points of discussion were a) whether to use KMAC or raw SHA-3 and b) the NIST compliance. KMAC uses SHA-3 internally, so the essential security properties of the constructions do not differ. NIST compliance has an interdependency on a) due to the way the SP 800-56C defines the key shares. Furthermore, NIST conformance requires specific orderings on the input of the key shares. All of these details we have been working on are only cosmetics. As I understand it, the different proposals in CFRG are not due to different views on what is a secure construction and what not, rather they are looking for the most efficient ones under certain assumptions – just as Dan explains in his response. > The CFRG chairs proposed adopting the topic; that wasn't controversial. > They also proposed, basically, an informational document covering all > options---but that was controversial. Ultimately the topic was adopted > with a plan of pulling together a design team to evaluate desiderata for > a document: > > https://mailarchive.ietf.org/arch/msg/cfrg/ZYd_q7QP17EtHtvSj60eSeJvkX0/ > https://mailarchive.ietf.org/arch/msg/cfrg/b63jMnt_3VA-wFAGmVyrXTnDY2o/ > > In July, the design team proposed a path of (A) identifying relevant > security properties, (B) surveying the literature, and (C) specifying > some initial combiners in light of B and A, making sure to cover at > least specific combinations of {P-256,X25519,P-384} and Kyber: > > https://mailarchive.ietf.org/arch/msg/cfrg/CwrVvm-J7o85TEWkG9RJxZwfXDY/ > > It's certainly not obvious how X-Wing could fit into that plan, given > that X-Wing is by definition specifically X25519+Kyber768. But I > wouldn't say anything is settled here; I'd expect further discussion in > CFRG of how many ECC options should be supported. > > Another issue is that, internally, X-Wing uses a combiner whose security > analysis relies on details of Kyber. I've raised objections to this from > a security-engineering perspective; but the more robust Chempat option > (which I favor) has triggered objections that it would cost Google > _millions_ of dollars. Again I wouldn't say anything is settled here. So far the vote of the OpenPGP (as the authors of draft-ietf-openpgp-pqc have understood it) was to specify a reusable KEM combiner, neither only a fixed combination of PQ and T algorithms nor a combiner that is restricted to a specific algorithm (or set of algorithms). The working group may of course change their opinion. So far only Paul (and Daniel Huigens?) have voiced the concrete interest in the X-Wing construction. However, in the view of the upcoming NIST recommendations for KEMs in SP 800-227, I propose to wait before the WG starts to engage in this discussion. It makes more sense to discuss this matter when a concrete standardized option is on the table – that is at least my view. > Certainly no consensus has been declared yet on any specific options, > nor can I imagine how consensus could be declared at this point given > the actual contents of the discussions. When CFRG hasn't declared > consensus, it's weird to see an IETF AD claiming outside CFRG that CFRG > "will" adopt something or that consensus "seems" to exist in CFRG. I share this view and I plead in favour of only considering in OpenPGP at maximum adopted work of other WGs, and ideally only such that has already reached a substantial degree of stability. Best regards, Falko >> You can always lend a helping hand to the people involved there or >> express your support for the document on the cfrg list to ensure the >> community there is aware. > I've already been providing detailed input to the discussion (see, e.g., > https://mailarchive.ietf.org/arch/msg/cfrg/8rs9KcfxfKvgn6FKGs7jMenmPQA/) > and in particular pointing out issues in this particular document > (ibid). So I'm baffled by your sentence here. > > ---D. J. Bernstein > > _______________________________________________ > openpgp mailing list --openpgp@ietf.org > To unsubscribe send an email toopenpgp-leave@ietf.org -- *MTG AG* Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: falko.strenzke@mtg.de Web: mtg.de <https://www.mtg.de> ------------------------------------------------------------------------ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy <https://www.mtg.de/en/privacy-policy>
- [openpgp] WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] BSI view on KEM combiners Kris Kwiatkowski
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners D. J. Bernstein
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Ehlen, Stephan
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Daniel Huigens
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Falko Strenzke
- [openpgp] Re: WG: BSI view on KEM combiners Paul Wouters
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker
- [openpgp] Re: WG: BSI view on KEM combiners Phillip Hallam-Baker